Unconditional version-check fetch to react-grab.com on start() with no opt-out
Author: pranaysuyashCreated Aug 26, 2026Updated Aug 26, 2026
Summary
packages/scan/src/web/utils/check-react-grab-version.ts:14-37 (called from packages/scan/src/core/index.ts:470) fetches:
https://www.react-grab.com/api/version?source=react-scan&v=<bundled version>&t=<Date.now()>on every start(). This is a non-consented phone-home that leaks visitor IP/UA to a third-party domain, and there is no opt-out flag.
Mitigating factors
start()early-returns in production builds (core/index.ts:462-468) unlessdangerouslyForceRunInProduction, so this mainly fires in dev.- Payload is minimal (version + timestamp), but IP/UA are inherent to any HTTP request.
Suggested fix
- Gate behind the same telemetry/DO_NOT_TRACK conventions used elsewhere in the ecosystem (react-grab CLI honors
DO_NOT_TRACK; react-doctor has--no-telemetry). - Document the ping in the README regardless.
Note: react-scan/lite already does this exactly right — event POSTing is strictly opt-in, and lite.test.ts:83-84 asserts lite never touches fetch/XHR. Applying the same philosophy to the version check would make the package consistent.
Source: aidenybai/react-scan